A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).
References
Link | Resource |
---|---|
https://www.fxc.jp/news/Product_Overview-LoadMaster_Release_Notes.pdf | Release Notes Third Party Advisory |
http://packetstormsecurity.com/files/131284/Kemp-Load-Master-7.1-16-CSRF-XSS-DoS-Code-Execution.html | Exploit Third Party Advisory VDB Entry |
https://www.exploit-db.com/exploits/36609/ | Exploit Third Party Advisory VDB Entry |
Configurations
Information
Published : 2020-01-08 09:15
Updated : 2020-01-13 08:10
NVD link : CVE-2014-5287
Mitre link : CVE-2014-5287
JSON object : View
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Products Affected
kemptechnologies
- loadmaster